[Snyk] Fix for 2 vulnerabilities#86879
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-LODASH-15869619 - https://snyk.io/vuln/SNYK-JS-LODASH-15869625
|
🤖 CI Fix Blocked — Environment Restriction Root Cause: All CI checks are failing because Mismatched packages:
Why I can't fix it: The sandbox environment blocks Manual fix (takes ~30 seconds): git checkout snyk-fix-24afddc4302d5e52e7ab56cd5959281c
npm install --package-lock-only
git add package-lock.json
git commit -m "Update package-lock.json to match Snyk dependency bumps"
git push |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7149294053
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
The v6 major version of this plugin changed to ESM-only, breaking the legacy config name used via FlatCompat. Import the plugin directly and register it in the plugins section instead. Co-authored-by: Gabriel Valforte <Valforte@users.noreply.github.com>
|
Fixed the failing ESLint check. Root cause: The Snyk upgrade bumped Fix: Imported the plugin directly and registered it in the flat config |
The v6 major version is incompatible with the ESLint config's use of FlatCompat and the plugin:@dword-design/import-alias/recommended config. Revert this package to v5 while keeping the other Snyk security fixes (concurrently, portfinder, @types/concurrently). Co-authored-by: Gabriel Valforte <Valforte@users.noreply.github.com>
…d5959281c' into snyk-fix-24afddc4302d5e52e7ab56cd5959281c Co-authored-by: Gabriel Valforte <Valforte@users.noreply.github.com>
Co-authored-by: Gabriel Valforte <Valforte@users.noreply.github.com>
|
Pushed a corrected fix (reverted my previous ESLint config approach). Root cause: The Snyk upgrade bumped Fix: Reverted |
|
@MarioExpensify Please copy/paste the Reviewer Checklist from here into a new comment on this PR and complete it. If you have the K2 extension, you can simply click: [this button] |
1 similar comment
|
@MarioExpensify Please copy/paste the Reviewer Checklist from here into a new comment on this PR and complete it. If you have the K2 extension, you can simply click: [this button] |
Reviewer Checklist
Screenshots/VideosAndroid: HybridAppAndroid: mWeb ChromeiOS: HybridAppiOS: mWeb SafariMacOS: Chrome / Safari |
MarioExpensify
left a comment
There was a problem hiding this comment.
Looks like we had just one major version update, but everything seem to be working fine. Moving forward with merge.
|
🚧 @MarioExpensify has triggered a test Expensify/App build. You can view the workflow run here. |
|
🧪🧪 Use the links below to test this adhoc build on Android, iOS, and Web. Happy testing! 🧪🧪
|
|
✋ This PR was not deployed to staging yet because QA is ongoing. It will be automatically deployed to staging after the next production release. |
|
🚀 Deployed to staging by https://github.com/MarioExpensify in version: 9.3.52-0 🚀
Bundle Size Analysis (Sentry): |
|
🚀 Deployed to production by https://github.com/roryabraham in version: 9.3.52-9 🚀
|
Explanation of Change
Fixed Issues
$
PROPOSAL:
Tests
Offline tests
QA Steps
// TODO: These must be filled out, or the issue title must include "[No QA]."
PR Author Checklist
### Fixed Issuessection aboveTestssectionOffline stepssectionQA stepssectiontoggleReportand notonIconClick)src/languages/*files and using the translation methodSTYLE.md) were followedAvatar, I verified the components usingAvatarare working as expected)StyleUtils.getBackgroundAndBorderStyle(theme.componentBG))npm run compress-svg)Avataris modified, I verified thatAvataris working as expected in all cases)Designlabel and/or tagged@Expensify/designso the design team can review the changes.ScrollViewcomponent to make it scrollable when more elements are added to the page.mainbranch was merged into this PR after a review, I tested again and verified the outcome was still expected according to theTeststeps.Screenshots/Videos
Android: Native
Android: mWeb Chrome
iOS: Native
iOS: mWeb Safari
MacOS: Chrome / Safari